Security headers checker

Fetching...

What this checks

A fixed set of response headers browsers use to restrict what a page is allowed to do, each one closing off a different class of attack: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and the three Cross-Origin-* isolation headers.

Presence is not the same as correctness

This reports whether each header is present and shows its value - it does not grade whether that value is well configured. A site can have a Content-Security-Policy that is technically present but so permissive it blocks nothing meaningful; this tool will still show it as present, so the value column is worth reading, not just the pass/fail column.

Why a header might legitimately be missing

Not every header suits every site - X-Frame-Options matters far more for a page that must never be framed (a login form) than for one that is meant to be embedded elsewhere. A missing header is worth investigating, not automatically treated as a bug.

Related tools

For the full raw header list, see the HTTP headers checker.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.

Add this tool to your website. Free, responsive, no ads, no sign-up - copy one line of code.

Embed this tool